CreticaActivation.exe

CreticaActivation

Vicentas

Publisher:
Vicentas  (signed and verified)

Product:
CreticaActivation

Version:
4.00.0041

MD5:
3f6d25a77d4ae7d9a387a2e2169e3111

SHA-1:
c834c02dac95b26ac94e2df41e76f527115836fa

SHA-256:
1558107f0fe1f0e7bd9d8bc357f427e75e56caac8f0ac5ebd595fd2ee4d46072

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/18/2024 4:29:44 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.VbCrypt.250
9.0.1.0218

File size:
267.7 KB (274,080 bytes)

Product version:
4.00.0041

Copyright:
Vicentas

Original file name:
CreticaActivation.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\data\offline\bbe5de4d\7193d1cb\creticaactivation.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/20/2011 2:00:00 AM

Valid to:
12/20/2013 1:59:59 AM

Subject:
CN=Vicentas, O=Vicentas, POBox=152, STREET=Postbox 152, L=Voss, S=Hordaland, PostalCode=5701, C=NO

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
21CA3102AB468AED5217FA7174A6EF1D

File PE Metadata
Compilation timestamp:
3/5/2012 12:15:13 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:K3ZrInRR84iY8/yadz27+kM1fQ07tYwKv:crdG+LFTtYwKv

Entry address:
0x8C008

Entry point:
EB, 16, 8B, 15, 00, C0, 48, 00, FF, 32, 8F, 05, 00, C0, 48, 00, EB, 06, 8F, 05, 00, C0, 48, 00, B8, 04, A0, 48, 00, 83, 38, 00, 74, 20, 50, FF, 70, 04, FF, 30, 50, 83, 04, 24, 08, E8, E6, 09, 00, 00, 83, C4, 0C, 58, 8B, 10, C1, E2, 02, 01, D0, 83, C0, 08, EB, DB, E9, 89, 12, 00, 00, 56, 69, 72, 74, 75, 61, 6C, 50, 72, 6F, 74, 65, 63, 74, 00, 00, 00, 00, 00, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 6B, 65, 72, 6E, 65, 6C, 33, 32, 00, 00, 00, 00, 4C, 6F, 63, 61, 6C, 41, 6C, 6C, 6F, 63, 00, 00...
 
[+]

Entropy:
7.7079  (probably packed)

Code size:
224 KB (229,376 bytes)

Scan CreticaActivation.exe - Powered by Reason Core Security